Currently users can view, edit and delete entities of other users:
- Login as User-1
- Create pad and remember id of that pad from URI.
- Login as User-2
- With the pad id from 2. you can view and edit the pad.
Deleting the pad doesn't work, but unfortunately deleting the note of another user does.
The authenticated user should be checked against the owner of entities.